[Xangle RWA Series] Compliance

Table of Contents
1. Why Compliance Gets Complicated in Tokenization
2. Regulations That Apply to Tokenized Assets
3. Compliance Functions and the Players Behind Them
4. Compliance Cases by Asset Type
5. Conclusion
1. Why Compliance Gets Complicated in Tokenization
Efforts to handle real-world assets on blockchains are multiplying quickly. US Treasuries and money market funds now circulate as tokens at a scale of billions of dollars, and gold, private credit, and equities are being issued on-chain as well. An earlier report mapped this market as a whole, broken out by asset class. This series zooms in on one section of that map. The subject here is compliance, meaning the work of meeting regulatory obligations. This piece sets out which regulations apply to tokenized assets, then examines the players (vendors) that carry that compliance out and the cases where they show up in practice.
Tokenization usually calls technology to mind first: which chain to build on, which standard to issue under, how the token lands in a wallet. But as blockchains and token standards have spread, turning an asset into a token is no longer the hard part. Issuance is comparatively easy. The difficult work begins after it.
Suppose a fund interest has been tokenized and issued into an investor's wallet. The issuer here means the party that creates a tokenized product and brings it to market. When an asset manager tokenizes a fund, the manager is the issuer; when a company tokenizes its own assets, the company is. Regulatory obligations fall on the issuer in the first instance. Across the lifecycle, from issuance through circulation in the market and on to redemption, there are things the issuer has to keep verifying.
Who actually uses this wallet. Whether this wallet is permitted to send tokens to another wallet. Whether the receiving wallet is connected to a sanctioned party or to criminal proceeds. Whether the fund still holds enough real assets to back every token issued. And whether the smart contract code executing all of these controls works as intended. These checks repeat from the moment a token is issued until it is redeemed, and this is where most of the time and cost of compliance concentrates.
What makes this ongoing post-issuance verification hard is that work handled in one place in traditional finance is scattered across many places in tokenization. The obligations themselves are not new. Know Your Customer (KYC), anti-money laundering (AML), and accredited investor screening have been settled practice in traditional finance for decades. In traditional finance, all of this converged on the account at a financial institution. When an investor opened an account at a brokerage, identity verification, transaction monitoring, transfer restrictions, and ownership records ran through that single account as one continuous chain. The account was the one center holding everything together.
Tokenization has no such center. A wallet is a different kind of object from an account. Anyone can create one in seconds with no screening, one person can hold many of them, and if the private key leaks, even the party actually controlling the wallet changes. An account has a bank that fixes the name on it and maintains it. A wallet has no such administrator. So the information that used to sit inside the account is now split across several places. The investor's identity lives in a centralized system, the record of asset holdings lives on the blockchain, the underlying asset sits with a custodian, and the transfer rules live in a smart contract.

Tokenization compliance, in the end, is not about writing new regulation. It is about rearranging the controls that used to converge inside an account so that they work across wallets and blockchains. Because investor identity, holding records, the underlying asset, and transfer rules now sit in different places, the central question is which parties and systems connect them, and how that chain gets enforced without a break across issuance, circulation, and redemption.
This piece therefore separates two questions. The first sets out which regulations apply, based on the rights a token carries, the jurisdiction of issuance and sale, and the parties transacting. The second breaks compliance into investor verification, anti-money laundering, transfer control, asset verification, and smart contract security, looks at the leading players in each function, and then works through four cases to see how compliance actually gets arranged.
2. Regulations That Apply to Tokenized Assets
Determining which regulations apply to a tokenized asset means separating the token as a technical format from the legal right the token represents. Recording an asset on a blockchain does not erase the character of the existing right, nor does it turn every token into a virtual asset for regulatory purposes. Tokenize a share or a fund interest and securities regulation still holds. Package a claim to redeem dollars or a right to withdraw a physical commodity, and the rules built for stablecoins or for commodity structures apply instead.
Three questions follow, in order. First, what underlying asset and what rights the token carries. Second, what anti-money laundering and sanctions controls financial institutions and VASPs perform. Third, in which country the token is issued and sold, and therefore which jurisdiction's rules bind it.

2-1. Rights in the Underlying Asset

The rights a token holder receives fall into four broad categories. The largest share belongs to tokens carrying securities rights. Recording something that was already a security, such as a share, a bond, or a fund interest, as a token leaves its character as a security untouched. The securities rules governing who it can be sold to, under what conditions it can be transferred, and how ownership must be recorded all remain in force. In March 2026, the US SEC and CFTC issued a joint interpretation classifying tokenized securities as digital securities under SEC jurisdiction. It is not only shares and bonds: real estate and private credit also read as securities once structured as equity or beneficial interests, which is why a substantial portion of tokenized assets land in this category.
Payment stablecoins work differently. The right embedded in these tokens is a claim to redeem a currency such as the dollar at par, so they are regulated apart from securities, around how much reserve is held and in what form, and how redemption is guaranteed. In the United States, the GENIUS Act governs this area. Tokens that simply represent ownership of, or the right to withdraw, a physical commodity such as gold or another raw material are not securities. On top of the common AML baseline, what attaches is verification that the physical asset is actually in storage, with no separate securities regime layered on. Structure that same physical asset as an investment contract, however, with the issuer promising to manage it and generate a return, and it reads as a security again and has to comply with securities regulation.
2-2. Virtual Assets
Anti-money laundering rules attach less to the token format itself than to the parties and the activities that exchange, transfer, and safekeep value. The FATF defines a virtual asset service provider (VASP) as any party not already captured by existing financial institution rules that conducts, as a business on behalf of others, the exchange between virtual assets and fiat currency, the exchange between virtual assets, the transfer of virtual assets, the safekeeping of virtual assets, or financial services related to the issuance and sale of virtual assets. National regimes build on this to register or license VASPs and impose obligations covering customer due diligence, transaction recordkeeping, suspicious transaction reporting, and the Travel Rule.
VASP rules therefore do not apply uniformly across every tokenization structure. Where a broker-dealer or a custodian handles a tokenized security, the existing financial institution AML framework does the work. Where a party intermediates the exchange, transfer, or safekeeping of virtual assets, the VASP regime applies. Direct transfers between personal wallets have no intermediary verifying the user, so the same KYC does not happen at the protocol level. Controls instead concentrate at the points where a regulated business enters: issuance and redemption, exchanges, custodians, and the on-ramps and off-ramps connecting fiat currency to virtual assets. What settles the question is not what the token is called, but who intermediates the movement of value and under which license.
Sanctions apply a different test from AML. AML gauges illicit finance risk through the customer, the source of funds, and transaction patterns. Sanctions ask whether the counterparty, or an asset that party owns or controls, is connected to a prohibited target. Even funds raised entirely legitimately can produce a violation once they move to a sanctioned party, and this obligation applies regardless of whether the payment instrument is a virtual asset or fiat currency. The specific lists and the scope of the prohibitions, however, shift with the foreign policy and national security positions of the UN and individual states.
2-3. Jurisdiction of Issuance and Sale
What the jurisdiction determines is twofold: how far the investor must be screened, and how transfers of the issued token must be controlled. What follows takes security tokens as its basis; payment stablecoins and physical commodity tokens follow regulatory regimes separate from securities.
United States
A public offering requires registering the securities with the SEC. A private placement under Rule 506(c) is exempt from registration, but in exchange every purchaser must be an accredited investor. An investor's self-certification does not satisfy that requirement, so the issuer has to review income or asset documentation directly or obtain written confirmation from a broker-dealer or a certified public accountant. A fund relying on the 3(c)(7) exception limits its investors to qualified purchasers.
Securities issued this way become restricted securities, meaning resale restrictions persist well past issuance and the issuer bears responsibility for managing them. The reference point for a transfer of ownership is the official register maintained by the issuer or its transfer agent. The blockchain either constitutes that register itself or serves as a secondary record that updates a separate off-chain register. Whether a token transfer amounts to a legal transfer of ownership depends on how those two have been connected.
EU
A public offering requires a prospectus approved by a member state supervisory authority. Filing an approved prospectus permits sale to retail investors with no screening of income or assets, and an offering limited to qualified investors is exempt from the prospectus obligation.
The legal effect of a blockchain record and the mechanics of transferring ownership are set by member state law rather than at EU level. Germany's Electronic Securities Act gives blockchain registers the same legal effect as paper certificates, and Luxembourg has a control agent maintain the issuance account and holder records for securities issued on a distributed ledger. The specifics of transfer restrictions likewise vary with the product structure and the applicable member state law.
Singapore
A public offering requires registering a prospectus with MAS, and limiting the offer to institutional investors and accredited investors exempts the issuer from that registration. Securities acquired under the exemption can only be resold to institutional or accredited investors in turn.
There is no separate regime recognizing a blockchain record as a legal register. Whether the token functions as the official record of ownership is settled by the offering documents and the existing books, which leaves the issuer to design the reconciliation between on-chain records and the legal register itself.
Abu Dhabi Global Market
A public offering requires a prospectus approved by the FSRA, and an offering meeting certain conditions, such as being made to professional clients, can proceed as an Exempt Offer.
Tokenized securities are classified as Ledger-Based Securities, and the blockchain record itself is recognized as the register of the security. The issuer and a licensed trading or clearing facility manage access rights to the distributed ledger, and those rights are what control investors' holdings and transfers. Recording changes of ownership, maintaining the issuer register, and minting and burning tokens are all performed by the licensed infrastructure.

3. Compliance Functions and the Players Behind Them
As set out above, a tokenized asset has to satisfy virtual asset regulation, underlying asset regulation, and the rules of the country of sale all at once. That means real work follows: verifying identities, tracing funds, controlling transfers, and verifying assets. The businesses that carry out this work are the subject of this chapter.
There are five things to check: who uses the wallet, where the funds moving through it come from, whether a wallet is eligible to receive the token, whether the assets backing the token actually exist, and whether the code executing these controls is sound. Each of the five checks a different object and demands a different capability. Telling a forged ID from a real one, tracing on-chain fund flows, and inspecting physical bars in a vault are not tasks one company can reasonably cover end to end. That is why compliance for tokenized assets splits into five functions: 1) investor verification, 2) anti-money laundering, 3) transfer control, 4) asset verification, and 5) smart contract security.

An issuer either picks a player for each of the five functions and assembles them, or hands the work to a player that bundles several functions together. This choice determines who bears responsibility when a rule is broken. US federal law places obligations such as identity verification and suspicious activity reporting on the license holder that actually performs the work. So when a licensed player performs verification in its own name, that player carries the liability as well. Use a player that supplies only tooling without a license, and the liability stays with the issuer. Which player an issuer uses for each function is, in effect, a decision about how much of that liability it keeps.
3-1. Investor Verification
What investor verification checks is the same as what happens when an account is opened in traditional finance. An individual is verified against an ID document (KYC). A corporate entity is verified against its registration and ownership structure, and then further, through to the beneficial owner behind it (KYB). Verifying only the entity on paper would leave a sanctioned beneficial owner behind it undetected. In offerings where eligibility is restricted, screening extends to whether the investor meets income or asset thresholds. What changes is the object being verified. It is no longer an account maintained by a brokerage but the investor's wallet, and a wallet has no party that verifies or maintains its user.
Tokenization therefore rebuilds, at the wallet, what the account used to do. Identity and eligibility are verified at the moment the wallet connects, and the original ID documents and supporting evidence used in that check are held in the centralized systems of the issuer or the verification provider. Only the result, that the wallet has passed and is eligible, is written to the wallet address on-chain. This eligibility has to remain readable on-chain, because that is what lets the transfer stage later judge whether a wallet is eligible to receive the security and block transfers to wallets that are not.
The check is also not a one-off. Nothing guarantees that the investor who was verified for a wallet keeps using it, and an eligibility once granted does not simply persist. Sanctions lists get updated and accredited status expires with time, so the verification has to be maintained on an ongoing basis.
Securitize
Securitize is a tokenization platform that handles securities issuance, investor verification, transfer agency, and secondary trading within a single licensing structure. The component covering investor verification is Securitize ID, and it supplies most of what investor verification requires. Individual investors are verified through ID documents and facial matching. Corporate entities are verified through their control structure and on to the beneficial owner, and eligibility to acquire the security is screened as well. Once a passing investor's wallet is granted eligible status, Securitize's DS Protocol uses that status for transfer control, making this a player that covers both investor verification and transfer control.
Securitize's strength is that it absorbs the regulatory obligations attached to investor verification inside its own license. Selling a tokenized security requires a broker-dealer license to intermediate the security, and a firm holding that license must run a Customer Identification Program (CIP) under the Bank Secrecy Act when it takes on a customer. Securitize's affiliate, Securitize Markets, is an SEC-registered broker-dealer, so that affiliate verifies investors directly. Most players supply verification software while the regulatory obligation stays with the issuer. Here, an issuer does not need to stand up its own broker-dealer or build a CIP framework, because investor verification and the CIP obligation are both resolved through Securitize's license. Token issuance, investor verification, and transfer control can all be handed to Securitize at once.
iCapital
iCapital is a distribution platform that connects access-restricted alternative investment products, such as private equity and hedge funds, to banks and brokerages. Products created by Blackstone or KKR reach investors through it. Only accredited investors meeting income or asset thresholds can buy these products, so the selling side has to confirm that a buyer qualifies. In 2025, iCapital acquired Parallel Markets and introduced an investor passport that requires this confirmation only once. An investor whose status has been confirmed then uses that passport when buying other products, with no re-verification.
iCapital's strength is that it takes on the liability attached to this verification under its own license. Its affiliate, iCapital Markets, is an SEC-registered broker-dealer, and that broker-dealer performs accredited investor verification for private placements in its own name and issues a confirmation letter. Because US private placement rules recognize this letter as an accepted method of verification, an issuer can rely on it and shed the burden of verifying accredited status itself. This is where iCapital departs from software vendors that pass along a verification result while leaving the liability with the issuer.
Sumsub
Sumsub supplies investor verification software. Global crypto exchanges such as Bybit and Bitget use it to verify identity when onboarding users. Individuals are verified through ID documents and facial matching, corporate entities through their control structure and on to the beneficial owner, and the results are then screened against sanctions lists to filter out high-risk parties. Ongoing monitoring of investors who have already passed verification sits on top of this, so the whole process runs on a single piece of software, from onboarding through to ongoing monitoring.
Sumsub's strength lies in bundling these functions together. Sourcing identity verification, sanctions screening, and ongoing monitoring separately makes integration cumbersome. Sumsub packages them into one product and has become the most widely used verification tool in the crypto industry as a result. It remains software without a license, however, so while it performs the verification, the customer due diligence liability that follows from the result stays with the issuer that deployed it.
Entrust (Onfido)
Entrust is a verification company specializing in determining whether an ID document is genuine and whether the applicant is the person it depicts. It acquired the identity verification specialist Onfido in 2024 to secure that technology. Services such as Revolut and Bitstamp have used Entrust for user verification. It examines the authenticity and format of government-issued identity documents, captures the applicant's face and matches it against the photo on the document, and catches attempts to impersonate someone using forged IDs or deepfakes.
Entrust's strength is the accuracy of this identity check. Its biometric verification, which determines whether a captured face belongs to a live person, holds an international certification (iBeta Level 2), and Onfido has reported a false acceptance rate, meaning the share of fraud attempts that pass as legitimate, of around 0.01%. Entrust is likewise a software vendor without a license, so it hands over the verification result and nothing more. The responsibility for accepting that person as an investor rests with the issuer that deployed it.

3-2. Anti-Money Laundering and Transaction Monitoring
If investor verification checks who owns a wallet, anti-money laundering checks the funds that wallet sends and receives. An identity verified at onboarding captures only that moment in time. An investor who passed can later transact with a sanctioned party, criminal proceeds can move through the wallet, and if the private key leaks, the party using the wallet changes outright. On-chain transactions are also irreversible, so by the time a risk surfaces, the funds have most likely already been laundered through multiple wallets and DeFi protocols. Hence the need to monitor a wallet's funds and transactions continuously, well past onboarding.
This anti-money laundering work runs along two tracks. The first is transaction monitoring, or Know Your Transaction (KYT). It analyzes the risk in wallets and transaction flows on-chain, tracing whether a wallet connects to a sanctioned party, hacked funds, or a route such as a mixer, and periodically re-screening existing investors against sanctions lists as those lists are updated. The second is the Travel Rule, which requires that information about the originator and the beneficiary travel alongside transfers above a threshold between institutions. In interbank wires, that information is bundled in from the start. In on-chain transfers, it is not even apparent whether the counterparty is a regulated business or a personal wallet. Issuers therefore need a separate network to identify the counterparty and exchange information with that business.
Monitoring systems screen individual transactions in real time and generate an alert whenever a risk indicator is triggered: a sanctioned address, mixer exposure, an anomalous transaction pattern, or a threshold breach. Once an alert fires, a compliance officer reviews the fund flows behind that transaction, and if it is judged suspicious, reports it to the authorities within a set deadline. The basis for the review, what was checked, and how the judgment was reached all have to be documented, because that record is what allows the firm to answer a regulatory examination later.
Chainalysis
Chainalysis has led the on-chain analytics market since 2014. Its strengths are rooted in law enforcement and regulatory work. Investigative authorities around the world, including the US Internal Revenue Service and the Federal Bureau of Investigation, have used Chainalysis to trace criminal proceeds, and the address labels and fund flow data accumulated through that work became the foundation for its later commercial compliance products. Years of accumulated data and investigative capability are this company's assets.
What it analyzes is the risk in wallets and transactions. Labeling links an on-chain address to the real party behind it, whether an exchange, a mixer, a sanctioned entity, or a darknet market. Clustering groups the addresses controlled by the same owner. Exposure analysis calculates how many hops separate a given wallet from a risky source of funds. These steps produce a risk score for each wallet and transaction. That score feeds transaction screening and wallet assessment, and when a risk signal appears, the investigation tool Reactor traces where the funds came from and where they are headed. Those tracing results become the basis for a report to authorities or the supporting evidence when requesting an asset freeze.
Layered on top is the fact that monitoring continues well past onboarding. A counterparty that raised no concerns at the time of a transaction may later be designated as sanctioned or shown to be tied to criminal activity, at which point the risk of that past transaction is reassessed retroactively and the transaction itself can become newly reportable. This filters out risk that the check performed at investor verification could never catch.
Chainalysis brings the same analytical capability to tokenized assets. Its monitoring is integrated into Hadron, the platform built by stablecoin issuer Tether for real-world asset tokenization, where it monitors transactions and detects risk across the issuance and circulation of stablecoins, bonds, and commodity-backed tokens.
TRM Labs
TRM Labs traces wallets and transactions to determine connections to sanctioned parties and illicit funds, and assigns a risk score. Its underlying methods, labeling, clustering, and exposure analysis, resemble those of Chainalysis. What separates the two firms is how that risk information gets put to use. TRM's emphasis is on sharing and responding to threats in real time.
The centerpiece is the Beacon Network. Investigative agencies, exchanges, and stablecoin issuers share confirmed crime- and sanctions-related address information into the network. The moment flagged funds arrive at a participating institution, an alert fires and that institution can hold or review the deposit. The design intercepts hacked, fraudulent, or sanctioned funds at the chokepoint, before they can be cashed out through an exchange. Once a risk is detected, the compliance team traces the fund flows with an investigation tool and can report the findings to the authorities.
Investigative agencies including the US Secret Service and Homeland Security Investigations use it. On the private side, users include payments and trading firms such as Circle, PayPal, Visa, and Coinbase, all of which need to catch criminal funds flowing into payment networks and exchanges quickly. Circle and PayPal among them are the issuers of USDC and PYUSD respectively, which means the real-time monitoring an issuer needs is being proven out in the operation of major stablecoins.
Elliptic
Elliptic also traces and investigates on-chain transactions, but its focus is on the ecosystem as a whole rather than the individual transaction. Where the previous two players lean toward assessing the risk of each wallet, Elliptic lets an issuer look at the risk surrounding the token it has issued. It continuously monitors which secondary markets the token trades on, which wallets hold it, and how the risk exposure of the whole ecosystem shifts.
This gives it the most concrete link to tokenized assets among the three. In 2026, Elliptic announced support from launch for the blockchain Robinhood built for tokenized equities and RWA settlement, and Monerium, which issues a euro stablecoin, deployed Elliptic's product suite for risk management across its stablecoin ecosystem. For an issuer, Elliptic goes beyond a tool that screens individual transactions: it monitors what risks the token it issued is exposed to in the market. The more an issuer's tokens circulate permissionlessly, leaving it unable to directly control holders and counterparties, the more it needs this line of sight.
Notabene
Where the previous three players chase the flow of funds, Notabene identifies the parties to a transfer. Specialized in the Travel Rule, it runs the network that confirms which business is on the other side of a transfer and exchanges the information the rule requires.
The problem has been that no single protocol has emerged for exchanging Travel Rule information. When each business uses a different specification, the information the rule requires struggles to get through. Notabene bundles multiple protocols into one, so the information travels regardless of which specification the counterparty business runs. Before a transfer executes, it confirms who the counterparty business is, determines whether it is sanctioned, and supports the decision to hold the transfer when the conditions are not met.
It does not, however, hold its own investigative capability for analyzing wallet risk in depth, so it uses the wallet risk scores supplied by the three players above to inform those decisions. More than 2,000 virtual asset service providers are connected to Notabene's Travel Rule network, and cumulative transfer volume across it passed $2 trillion as of January 2026.

3-3. Transfer Control
When a regulated security is tokenized directly, the resulting token cannot move as freely as an ordinary token. The receiving wallet has to be a verified, eligible wallet, and it must not be one frozen as a sanctions target. Depending on the country or jurisdiction, some parties cannot hold the token at all. Tokens structured to track only the price, without carrying the underlying asset itself, sometimes trade without these constraints. Traditional finance handled such constraints at the final step of an ownership transfer. The transfer agent maintained the register of owners and, at the point of recording a transfer in that register, blocked transfers to ineligible parties.
On-chain has no such step. Once a token transfer executes on a blockchain it cannot be reversed, so a transfer to an ineligible wallet is hard to undo after the fact. The transaction monitoring described earlier is not enough on its own. Monitoring may detect the risk, but unless the transfer to an ineligible wallet is actually prevented, the control is not complete. Transfer control also differs in character from the areas above. With identity verification and transaction monitoring, the control software evaluates data and hands the result to the issuer. With transfer control, that result has to live inside the smart contract and be enforced directly on-chain.
Two pieces of work are needed together for this. One is recording the identity, eligibility, and jurisdiction confirmed at onboarding onto the wallet in a verifiable form. The other is reading that recorded status at the moment of transfer and blocking the transfer when the conditions are not met. Once eligibility to receive, sanctions status, and permitted jurisdiction are written to the token, the code inside the smart contract checks those conditions automatically on every transfer before executing it.
Transfer control does not end with configuring rules at issuance. A sanctions designation or a legal order can land at any time after issuance, and when it does, the issuer has to be able to freeze or claw back the tokens in a specific wallet. When an investor's status changes, the on-chain identity has to be updated too, and that update has to take effect from the very next transfer.
Tokeny
Founded in 2017, Tokeny provides the infrastructure that lets issuers issue tokens with compliance built in. That infrastructure rests on a token standard called ERC-3643. The common token standard (ERC-20) is designed so that anyone can send and receive freely. ERC-3643 is a permissioned token standard designed to check, before a transfer happens, whether the receiving wallet is eligible, and to reject the transfer when the conditions are not met. Tokeny led the development of the standard and supplies both the platform that operates it in practice (T-REX) and the on-chain identity framework that assigns identity to a wallet (ONCHAINID).
The mechanics split in two. ONCHAINID assigns the identity, eligibility, and jurisdiction confirmed at onboarding to the wallet in a verifiable form. A token issued under ERC-3643 then queries the receiving wallet's ONCHAINID on every attempted transfer, and the smart contract executes only after confirming for itself that the wallet is eligible and that the transfer breaches no rule. Transfers to ineligible wallets, transfers during a lock-up period, and transfers into prohibited jurisdictions are all rejected at the smart contract level. The authority to freeze or claw back the tokens in a specific wallet upon a sanctions designation or a legal order is built into this structure as well.
Tokeny's strength is that, as the party that created the standard, it supplies the infrastructure alongside it. ERC-3643 is an open standard anyone can use, but doing so means building the infrastructure yourself, from the contracts through to the identity framework. Tokeny delivers that in finished form, so an issuer can issue a compliance-embedded token without building it. Tokeny may supply the transfer restrictions, ONCHAINID, and the permissioning logic, but responsibility for whether the issuance complied with securities law resale restrictions, sanctions, and transfer agency rules stays with the issuer using it and with the transfer agent.
Securitize (DS Protocol)
As seen in the investor verification section, Securitize is a tokenization platform that handles issuance, onboarding, and transfer agency within a single licensing structure, and it supplies transfer control as one part of that structure. The foundation is the DS Protocol (Digital Securities Protocol). Tokenized securities issued by Securitize are built on this protocol, and its operating principle resembles ERC-3643 in that compliance rules are embedded in the token itself and checked on every transfer.
The difference is that this protocol is not used standalone. The DS Protocol controls transfers by reading investor eligibility confirmed through Securitize ID, and that identity verification, the issuance, and the transfer agency all interlock inside Securitize's own structure. The eligibility of an investor onboarded through Securitize ID at the verification stage is recorded on-chain, the DS Protocol permits or blocks token transfers based on that eligibility, and the resulting transfer record flows back into Securitize's transfer agency records.
This is where the character of the regulatory liability diverges from Tokeny. When the DS Protocol is used inside Securitize's licensing structure, responsibility for maintaining the owner register and for the outcomes of transfer control falls on the Securitize affiliate acting as transfer agent. Tokeny supplies the same transfer control function as a standalone standard for which the issuer is responsible. Securitize embeds it in an issuance structure for which Securitize itself is responsible. Issuance, transfer control, and the liability that comes with them can all be handed to Securitize at once.

3-4. Asset Verification
A blockchain records only how many tokens were issued and which wallets hold them. The underlying asset backing the token sits off-chain. Treasuries are held in an account at a custodian bank and gold in a vault, and neither that balance nor that inventory can be confirmed on-chain. An issuer can disclose its holdings, but nothing beyond the issuer's own assertion establishes that the disclosure is true. Issuers therefore commission this verification from an independent third party and publish the result as a report.
Who gets commissioned, and what form the check takes, depends on the underlying asset. Where cash and Treasuries are the underlying, an accounting firm is commissioned to perform a reserve attestation. The work compares the custody account balance on a reference date against the token supply in circulation at that same moment, confirming that reserves exist in the amount issued. Where fund interests are the underlying, the scope widens even though the same accounting firm does the work. Funds are subject to an annual audit regardless of tokenization, and an audit goes beyond comparing reserve balances: the accounting firm issues an opinion on the financial statements as a whole. The issuer passes that audit report on to investors. Where gold is the underlying, the object of the check shifts from accounting records to the physical bars in a vault. Whether the bars are actually there and match their stated purity and weight can only be established by weighing them and comparing against the records, so an institution whose business is inspection and certification takes on the work.
At present, only payment stablecoins are subject to a rule requiring verification of a token's collateral. The GENIUS Act requires one-to-one reserves, monthly reserve reporting, and examination of that reporting by a registered accounting firm, and mandates an annual audit of financial statements once outstanding issuance exceeds $50 billion. The frequency of verification and the qualification of the verifier are both fixed by the statute. No such rule covers tokenized assets outside stablecoins, yet issuers commission and publish the same verification anyway. Without showing investors that the underlying asset genuinely exists, there is no basis for trust. Because no rule applies, the issuer decides which firm to use, how often to verify, and how to disclose the result.
Big Four (Deloitte, KPMG, PwC)
Verification for major stablecoins and institutional-grade tokenized assets falls to large accounting firms such as Deloitte, KPMG, and PwC. Registered with the US Public Company Accounting Oversight Board (PCAOB), they hold the qualification and meet the independence requirements to perform statutory audits of listed issuers and broker-dealers. Deloitte has audited Circle's financial statements since fiscal year 2022, has attested to USDC reserves monthly since 2023, and attests to Ripple's RLUSD reserves monthly as well. KPMG has attested to PayPal's PYUSD reserves monthly since 2025.
In a reserve attestation, the accounting firm confirms the assets and the issued supply independently of each other. It queries the balance of reserve assets directly with the banks and asset managers holding them, confirms the quantity of tokens in circulation from the blockchain using its own infrastructure, and then issues an opinion on whether assets equaled or exceeded issuance at that moment. The monthly reports published by Circle, Paxos, and Ripple all run through this procedure.
The Network Firm
The Network Firm is a US certified public accounting firm specializing in crypto assets, with a focus on Proof of Reserves for stablecoins and tokenized assets. Alongside issuing attestation results as monthly or quarterly reports, it operates a service that pushes the same data on-chain (LedgerLens). It takes read-only access to custody accounts to establish balances, then feeds that data into Chainlink's Proof of Reserve oracle.
It has verified the holdings of the crypto exchange Kraken on a quarterly basis, and for xStocks, Backed Finance's tokenized equities service, it confirms and publishes whether issued tokens correspond to the custodied shares at ten-minute intervals.
Bureau Veritas
Bureau Veritas is an institution whose business is inspection and certification. It confirms the physical condition of goods and facilities on site and issues a report. It came out of trade and industry rather than finance, and gold storage inspection is one branch of that work. It has handled vault inspections for SPDR Gold Shares (GLD), the world's largest gold ETF, and on the tokenized asset side it inspected the vaults collateralizing Matrixdock's gold token (XAUm).
The inspection happens in the vault. An inspector weighs each stored bar individually, measures its purity, and then matches the serial numbers against the vault's inventory records. What was there on the inspection date, how many units, and the weight and purity of each are recorded in the report.

3-5. Smart Contract Security
The controls covered in the previous four areas all execute as code on-chain. The code inside the smart contract reads the investor eligibility result, that same code checks transfer conditions automatically, and the permission structure in the code carries out transfer controls such as freezes and clawbacks. IT systems in traditional finance are ledgers recording assets and nothing more, so when something fails, the institution can find it, correct it, and reverse the faulty entry in the ledger. In tokenization, the funds sit directly on top of the code. A defect in that code does not merely stop the controls above from working: the defect translates immediately into a loss of user assets.
This is what makes smart contracts especially dangerous. The code is public, so an attacker can find a defect first, and on-chain transfers cannot be reversed, so stolen funds are hard to recover. In 2025 alone, over $3.3 billion was stolen across more than 630 incidents, a substantial share of which originated in code vulnerabilities.
No law currently mandates a security audit of smart contracts. Existing rules already assign responsibility for outcomes, however, such as the accuracy of ownership records or the protection of customer assets, so when a code defect compromises those outcomes, that responsibility is hard to escape. Having an independent smart contract auditor review the code before deployment has accordingly become standard practice for Web3 projects and dApps generally. Auditing does not stop at deployment either. Upgrading a smart contract or changing its permission structure calls for another audit, and continuously detecting anomalies in deployed contracts falls into this area as well.
OpenZeppelin
When implementing tokens, access permissions, and upgrade structures, countless projects across the Ethereum ecosystem use the open-source contract library OpenZeppelin built. Supplying vetted code as a standard narrows the room for defects to enter from the development stage onward, and more than $35 trillion in value transfer and $250 billion in assets have moved through this library.
Its audit history is also the longest in the field. It has found over 10,000 vulnerabilities across more than 900 audits and has reviewed the code of major projects including the Ethereum Foundation, Coinbase, Compound, and Aave. It has run more than 70 audits with Compound, and audited the account abstraction standard (EIP-4337) three times with the Ethereum Foundation, surfacing numerous high-risk defects that could have led to fund theft.
Its link to tokenized assets is equally pronounced. OpenZeppelin states that all ten of the largest tokenized funds by market capitalization and nine of the ten largest stablecoins use its library. The library includes an ERC-3643 implementation for regulated security tokens and a tokenized vault standard representing shares in an asset pool, and Securitize's DSToken is built on OpenZeppelin base contracts as well. Its tools for monitoring deployed contracts (Relayer, Monitor) are published as open source, so issuers can install and run them on their own servers.
CertiK
CertiK is a comprehensive security firm whose work spans everything from smart contract audits to continuous monitoring, founded by computer science professors from Columbia and Yale. That academic lineage is the source of its core strength: formal verification. Beyond reviewing code line by line, CertiK layers in a method that mathematically proves a function behaves exactly as specified. The approach reaches past smart contracts to structures that are hard to check through code review alone, such as zkWasm zero-knowledge circuits, and to date it has uncovered more than 90,000 vulnerabilities.
Beyond pre-deployment audits, CertiK also monitors post-deployment risk through Skynet. Skynet tracks a smart contract's on-chain activity and social channels in real time to flag warning signs, and it supplies those scores and risk feeds to external services such as wallets and exchanges. CertiK also runs an RWA leaderboard that compiles security scores for tokenized assets, laying out risk signals across several dimensions, including code, operations, governance, and market, in a single view. Among these, issuers such as Ondo and Paxos, which have tokenized assets including Treasuries, stablecoins, and gold, have undergone CertiK audits.
Zellic
Zellic is an audit firm whose strength lies in probing vulnerabilities from an attacker's perspective. Founded by researchers who made their names in capture-the-flag (CTF) security competitions, it leans toward reconstructing gaps in code into actual attack paths rather than working down a list of known checks. Across 338 reviews in 2025, it found critical or high-risk defects in 153 of them, meaning serious vulnerabilities were latent in close to half the code it examined.
Its coverage reaches beyond Ethereum (EVM) compatible chains to Solana, the Move family (Aptos, Sui), Cairo, NEAR, and Cosmos, giving it strength in cross-chain code audits. On the tokenized asset side, it has audited Ondo Global Markets, Superstate, and Matrixdock's silver token (XAGm) and gold token (XAUm). It also covers structures that standardized checks alone tend to miss, such as bridges linking multiple chains, messaging infrastructure, and zero-knowledge circuits.
Cyfrin
Cyfrin is a full-service smart contract security firm that has placed particular weight on RWA and tokenized asset audits. By its own count it has performed 33 audits related to traditional finance and RWAs, and its clients are the issuers that define this market. It audited the Ondo Funds and USDY smart contracts, which include Ondo Finance's Treasury token (OUSG), and audited Securitize, the issuer behind BUIDL and the tokenized products of Apollo and VanEck. The scope of that work spans redemption, cross-chain bridges, Solana integration, the global transfer agent registry, and DSToken rebasing.
Where an RWA audit departs from an ordinary token audit explains this firm's specialization. Unlike a standard ERC-20 token, a tokenized security has a far wider verification surface: issuance, burning, redemption, net asset value calculation, transfer restrictions, forced clawbacks, freezes, and register reconciliation. Cyfrin has focused on covering that wider RWA verification surface.
Halborn
Halborn covers security across blockchain infrastructure as a whole rather than confining itself to smart contract code. Alongside contract audits it provides penetration testing, custody and key management review, and cloud security, and it counts both crypto companies and financial institutions among its clients. It audited the custody keys of Bank Frick, the Liechtenstein blockchain bank, and on the tokenized asset side it audited Securitize's DSToken smart contract, reviewing the security token logic from issuance and burning through investor registration, transfer restrictions, and redemption.

4. Compliance Cases by Asset Type
4-1. A Security Token That Includes US Investors: BlackRock's BUIDL
BUIDL is a tokenized fund issued by BlackRock. Interests in a fund investing in cash-equivalent assets such as short-term US Treasuries and repurchase agreements are issued as tokens, with a target value of $1 per token and yield paid out monthly in newly issued tokens. It sells to US investors without registering with the SEC, because the private placement rule under the Securities Act (Rule 506(c)) and the Investment Company Act exemption (3(c)(7)) waive the registration obligation on the condition that the offering is limited to accredited investors and qualified purchasers.
That condition determines BUIDL's compliance design. The moment a token moves to an ineligible wallet, the basis for the registration exemption disappears, so the issuer has to keep controlling who holds the token long after issuance. This is why BUIDL tokens transfer only between pre-approved wallets, with Securitize's smart contract and whitelist enforcing the restriction. When a token is lost or stolen, the transfer agent burns it and reissues a replacement.
Compliance is handled by licensed affiliates. Securitize Markets acts as the broker-dealer, taking on investor onboarding and subscriptions along with the Customer Identification Program (CIP) and anti-money laundering obligations, while Securitize Transfer Agent maintains holder records as the registered transfer agent. Fund assets are held in custody at BNY Mellon, and PwC audits the financial statements annually. An issuer looking to include US investors does not have many options. For a token issued under a registration exemption, circulation is confined to approved investors, and a license holder capable of enforcing that condition (Securitize) has to sit inside the issuance structure.
4-2. A Security Token That Excludes US Investors: xStocks
xStocks are tokenized securities tracking the economic performance of US equities and ETFs such as Apple and Tesla. Switzerland's Backed Finance designs the product, and a special purpose vehicle established in Jersey serves as the legal issuer. Token holders receive economic exposure linked to the price movement and dividends of the underlying share, but do not own the share directly and therefore hold no shareholder rights such as voting. Each token is backed one-to-one by underlying assets held with regulated brokers and custodians, and in the EU it circulates on the basis of a prospectus approved by the Liechtenstein supervisory authority. In the United States, it is not registered as a security and US persons are excluded from the offering.
Compliance concentrates at issuance and distribution. Direct issuance and redemption through Backed, and sales through partner exchanges such as Kraken, verify the user's identity, residence, and sanctions status, blocking users from restricted jurisdictions including the United States. The issuer does not, however, approve each on-chain transfer once the token has been issued. Unlike BUIDL, which moves only among whitelisted investors, xStocks can technically transfer permissionlessly. The issuer therefore controls primary issuance and redemption, centralized exchanges carry out customer due diligence and anti-money laundering under their own licenses, and secondary transfers occurring between personal wallets or on decentralized exchanges do not pass through that same onboarding procedure.
Leaving transfers permissionless raises the importance of collateral verification, meaning confirmation that the issued supply genuinely corresponds to the underlying assets. The Network Firm verifies the issuance and custody data Backed provides, and the result is published on-chain through Chainlink's Proof of Reserve oracle. What characterizes xStocks is that it moves the locus of control away from the token transfer itself and onto issuance and redemption, exchange access, and collateral verification. By excluding US investors and adopting a structure open to anyone, Backed made xStocks usable in DeFi and on decentralized exchanges.
4-3. A Payment Stablecoin: PayPal
PYUSD is a dollar stablecoin PayPal built for payments and remittances, with Paxos Trust Company, N.A. handling issuance and custody. One PYUSD redeems for one dollar, and because it is not a security, regulation centers on the issuer's charter, one-to-one reserves, and redemption capacity rather than on investor eligibility or resale restrictions. In December 2025, Paxos received conditional approval from the OCC and converted from a New York state trust company into a national trust bank, Paxos Trust Company, N.A. Since then, Paxos has carried out PYUSD issuance and reserve management under OCC supervision and the conditions of that approval.
Any user who has completed identity verification can acquire and hold PYUSD, with no accredited investor restriction, and can move it through services such as PayPal and the mobile payments app Venmo, or out to external wallets and across multiple blockchains. Compliance responsibility divides accordingly, following wherever the transaction takes place. Inside PayPal and Venmo, the platform's customer due diligence and transaction monitoring do the work, while Paxos handles issuance, redemption, reserve management, supply control, and issuer-level anti-money laundering obligations. Transfers between external wallets involve no platform onboarding, but the means of control do not vanish along with it: through the smart contract, Paxos can pause transfers, freeze specific addresses, and burn frozen balances pursuant to legal process.
For reserves, Paxos discloses the composition monthly and KPMG issues a separate attestation report. It confirms whether reserves back the PYUSD in circulation at a given point in time, a different scope from the annual audit that examines the financial statements as a whole. PYUSD has no transfer agent maintaining a holder register and approving every transfer the way BUIDL does. Instead, issuance, redemption, reserves, supply, and sanctions response authority all concentrate in the issuer, Paxos. The controls that split across multiple licensed parties in a security token are reorganized around the issuer in a stablecoin.
4-4. A Gold-Backed Token: Matrixdock
XAUm is a token issued against physical gold, with each token representing one troy ounce of LBMA-standard gold held in a vault. Because the structure tokenizes ownership of a physical commodity rather than functioning as a security or a payment stablecoin, regulation centers on the right to the gold, the existence of the physical metal, and its storage condition, rather than on investor eligibility or cash reserves. The gold is stored in Hong Kong and Singapore vaults operated by Brink's and Malca-Amit, and the issued supply is designed to correspond one-to-one with actual gold holdings.
The distribution structure diverges between primary issuance and secondary trading. Issuing or redeeming directly through Matrixdock requires registering an account and passing KYC, and US residents and sanctioned jurisdictions are excluded. Unlike a security token, however, accredited investor status is not verified. Secondary transfers of issued tokens run permissionlessly and open, so Matrixdock takes responsibility for customer due diligence and anti-money laundering at issuance and redemption while exchanges handle their own user onboarding and transaction monitoring. The issuer can restrict issuance, redemption, and service access where a legal violation or regulatory risk arises.
The compliance function that matters most for XAUm is verification of the physical asset. In July 2025, Bureau Veritas weighed and measured 421 gold bars held across three vaults in Hong Kong and Singapore, confirming that the bars' specifications matched the vault records. On-chain, a proof of reserve system compares the token supply against gold holdings, and the smart contract code undergoes a separate security audit. A bank balance can be confirmed by an accounting firm's inquiry, but a bar's serial number, purity, weight, and storage location require an on-site inspection. Once the collateral becomes physical, asset verification shifts from accounting review to physical inventory inspection, and that is the crux of XAUm.

5. Conclusion
This report examined compliance for tokenized assets by separating two questions: which regulations apply, and who executes them and how. The regulations that apply are determined by the rights the token carries, the jurisdiction of issuance and sale, and who performs the exchange, transfer, and safekeeping. Executing them in practice requires investor verification, anti-money laundering, transfer control, asset verification, and smart contract security to run continuously from issuance through redemption.
What emerges is that tokenization does not introduce new regulation. It rearranges the controls that used to converge inside an account in traditional finance so they fit wallets and blockchains. Investor identity lives in a centralized system, records of token holdings and transfers live on the blockchain, and the underlying asset sits with a custodian. The issuer has to reconnect this structure through multiple players, and choosing those players is not only a question of function. It decides who takes on the regulatory liability and how much of it stays with the issuer.
BUIDL, xStocks, PYUSD, and XAUm show how control structures diverge even when the underlying act of tokenization is the same. BUIDL circulates within approved wallets and a transfer agency framework and sells to accredited investors and qualified purchasers. xStocks concentrates regulation at the issuance and redemption stage and then opens secondary transfers freely, easing access for retail investors. For PYUSD, reserves and issuer control sit at the center; for XAUm, verification of the physical metal in the vault does. The split between permissioned and permissionless is likewise an outcome of the asset's rights, its jurisdiction, and where the liability gets enforced.
What an issuer settles first, then, is not the chain or the token standard. It is what rights the token carries, and to whom and in which jurisdiction it will be sold. Only after that can it decide which licensed parties and systems will connect each compliance function. Competitiveness in the tokenization market will turn less on the speed of putting assets on-chain than on the ability to enforce legal rights and regulatory obligations without a break across issuance, circulation, and redemption.
Disclaimer
I confirm that I have read and understood the following: The information contained in this article is strictly the opinions of the author(s). This article was authored free from any form of coercion or undue influence. The content represents the author's own views and does not represent the official position or opinions of CrossAngle. This article is intended for informational purposes only and should not be construed as investment advice or solicitation. Unless otherwise specified, all users are solely responsible and liable for their own decisions about investments, investment strategies, or the use of products or services. Investment decisions should be made based on the user’s personal investment objectives, circumstances, and financial situation. Please consult a professional financial advisor for more information and guidance. Past returns or projections do not guarantee future results.
Xangle or its affiliated partners own all copyrights of the written or otherwise produced materials and content provided on the platform. Any illegal reproduction of such content, including, but not limited to, unauthorized editing, copying, reprinting, or redistribution will result in immediate legal actions without prior notice.




